<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Firewall and Speed</title>
	<link>http://ask.metafilter.com/5586/Firewall-and-Speed/</link>
	<description>Comments on Ask MetaFilter post Firewall and Speed</description>
	<pubDate>Tue, 02 Mar 2004 14:59:54 -0800</pubDate>
	<lastBuildDate>Tue, 02 Mar 2004 14:59:54 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Firewall and Speed</title>
		<link>http://ask.metafilter.com/5586/Firewall-and-Speed</link>	
		<description>Geek Question:  I took a look at my router&apos;s firewall.  I&apos;m getting a number of DDos attacks.  Now, the firewall is acting all nice and blocking it...but, I&apos;m sure this causing a slow down in my surfing/net use, etc.&lt;br&gt;
&lt;br&gt;
Any ideas on how to make it stop?</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2004:site.5586</guid>
		<pubDate>Tue, 02 Mar 2004 14:24:14 -0800</pubDate>
		<dc:creator>filmgeek</dc:creator>
		
			<category>DDOS</category>
		
			<category>firewall</category>
		
	</item> <item>
		<title>By: malphigian</title>
		<link>http://ask.metafilter.com/5586/Firewall-and-Speed#118251</link>	
		<description>How do you know they are dDos attacks and not just regular old worms or other exploit scripts scanning for open ports and/or unpatched servers?&lt;br&gt;
&lt;br&gt;
If you were actually under a distributed denial of service attack by more than a few machines, you can bet you wouldn&apos;t be getting to AskMe.  What are you seeing in your logs?&lt;br&gt;
&lt;br&gt;
If these are just attempts to exploit vulnerabilities in web servers, don&apos;t worry about it, they hit everything.  It&apos;s just the background noise of the internet.  Pat your firewall and give it a cookie for a job well done.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5586-118251</guid>
		<pubDate>Tue, 02 Mar 2004 14:59:54 -0800</pubDate>
		<dc:creator>malphigian</dc:creator>
	</item><item>
		<title>By: zsazsa</title>
		<link>http://ask.metafilter.com/5586/Firewall-and-Speed#118272</link>	
		<description>You can&apos;t make it stop, unless somehow you got your ISP to firewall you on their end.  Or you went around to everyone&apos;s computer in the world and upgraded them all with the latest security patches.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5586-118272</guid>
		<pubDate>Tue, 02 Mar 2004 16:50:23 -0800</pubDate>
		<dc:creator>zsazsa</dc:creator>
	</item><item>
		<title>By: dejah420</title>
		<link>http://ask.metafilter.com/5586/Firewall-and-Speed#118340</link>	
		<description>Agreed.  I get about 6 Slammer attempts an hour...and I don&apos;t even have sql on this machine.  The amount of port scanning and worm propagation is just insane...but I understand your frustration, as my firewalls are working overtime too.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5586-118340</guid>
		<pubDate>Tue, 02 Mar 2004 20:00:40 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>
	</item><item>
		<title>By: filmgeek</title>
		<link>http://ask.metafilter.com/5586/Firewall-and-Speed#118370</link>	
		<description>Followup:&lt;br&gt;
&lt;br&gt;
There isn&apos;t a way for me to trace back and either totally block the offending IP addresses or notify &lt;b&gt; their ISP &lt;/b&gt; that their machines are infected?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5586-118370</guid>
		<pubDate>Tue, 02 Mar 2004 21:27:32 -0800</pubDate>
		<dc:creator>filmgeek</dc:creator>
	</item><item>
		<title>By: Danelope</title>
		<link>http://ask.metafilter.com/5586/Firewall-and-Speed#118379</link>	
		<description>&lt;i&gt;There isn&apos;t a way for me to trace back and either totally block the offending IP addresses or notify  their ISP  that their machines are infected?&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
There is, but it&apos;s quite impractical.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;1.&lt;/b&gt; Grab the IP address of the offending machine from your logs.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;2.&lt;/b&gt; Plug the IP into &lt;a href=&quot;http://www.arin.net/&quot;&gt;ARIN whois&lt;/a&gt; to determine who owns the netblock.  Sometimes, ARIN will provide an appropriate e-mail address (i.e. abuse@) in the domain record.  Sometimes, you&apos;ll have to access the netblock owner&apos;s site to locate an appropriate way to contact them.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;3.&lt;/b&gt; Draft a polite message explaining that one of their customers is either willingly or unknowingly launching an attack on your machine(s).  You absolutely must include the following: Your IP address, the IP address of the machine attacking you, a sample of the malicious traffic from your log files, and the date/time the attack occurred.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;4.&lt;/b&gt; If they&apos;re a large national or international company, you likely won&apos;t receive a reply beyond their standard autoresponder.  If they&apos;re a smaller local ISP, you will likely hear from an actual human being, and they may request further information.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;5.&lt;/b&gt; If, after a week, you still see traffic coming from the reported machine, you can attempt to send another e-mail, again politely explaining that you are still receiving attacks from this IP address.  Hopefully, the problem will be resolved.  Sometimes, particularly if the ISP is based in Asia, you&apos;ll be dismissed and no amount of complaint-filing will help.&lt;br&gt;
&lt;br&gt;
Now, here&apos;s the fun part: repeat this procedure for every one of the thousands of IP addresses you will undoubtedly log over a given period of time.  Unless you have a very small group of machines attacking you, or you tend toward masochism, this will grow tedious rather quickly.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5586-118379</guid>
		<pubDate>Tue, 02 Mar 2004 22:11:59 -0800</pubDate>
		<dc:creator>Danelope</dc:creator>
	</item>
	</channel>
</rss>
